Get in touch

info@ostwalden.co.uk

Monday – Friday, 09:00 – 20:00
Saturday & Sunday, 09:00 – 19:00, by appointment

In an emergency call 999, or Samaritans free on 116 123.

Legal

Privacy Notice

Last updated: 22 September 2026. Version 1.0. This is the first version of this notice.

This notice explains what Ostwalden does with information about you when you visit ostwalden.co.uk or send us an enquiry. Please read section 3 before you use the enquiry form. It is the part that matters most.

1. Who we are, and how to reach us

This website is run by OSTWALDEN LIMITED, a company registered in England and Wales with company number 17119228. Our registered office is Suite 5, 5th Floor City Reach, 5 Greenwich View Place, London E14 9NN. We trade as Ostwalden.

We are the controller for the information described in this notice. That means we decide why it is collected and what happens to it, and we answer for it.

For anything to do with your information — a question, a request, or a complaint — email info@ostwalden.co.uk, or write to us at the address above. Ostwalden has no employees. Xinze Guo, our sole director, is the person responsible for data protection here, and your message will reach him.

There is no telephone number. Everything reaches us by email or by post.

We have not appointed a Data Protection Officer

Article 37 of the UK GDPR requires a Data Protection Officer only in particular cases. We are not a public authority, we do not monitor people on a large scale, and we do not handle health information on a large scale. On what we do today, we are not required to appoint one, and we have not. We have recorded that decision, and we will look at it again before we start taking bookings.

Registration with the ICO

Almost every UK organisation that uses personal information for business purposes must pay a data protection fee and appear on the public register kept by the Information Commissioner's Office (the ICO). Our processing is not covered by any of the exemptions. We are completing that registration now, and our registration number will be shown here once it is issued: [to be confirmed].

2. What this notice covers, and what it does not

At the moment this website is a brochure. It tells you who we are and what we offer, and it gives you a way to get in touch. It does nothing else. Today we do not:

  • take payments, or hold any card or bank details;
  • let you book a session, or create an account;
  • publish a counsellor directory, reviews, ratings, a forum or a chat feature;
  • keep counselling notes or any clinical record;
  • use analytics, advertising or tracking technology of any kind.

The only information this site takes from you is what you type into the enquiry form, what your browser has to send to our server for the page to load at all, and a short operational record our server creates when an enquiry is sent: a reference number, the date and time, a scrambled one-way version of your IP address, a spam score and the service you selected. That record does not contain anything you wrote. Section 4 sets it out in full, with how long we keep it. That is what this notice is about. Section 15 explains what will change when bookings go live.

Our service is for adults aged 18 or over who live in the United Kingdom. We do not offer it to people living in the European Economic Area.

3. The enquiry form, and information about your health

We need to be straightforward about this, because a message box on a counselling website is not an ordinary contact form.

We do not ask you about your health

The form asks for five things and no more: a name, which can be a first name or a nickname; an email address; which service your enquiry is about, chosen from a short list (individual counselling, couples counselling, low-cost counselling, working with us as a counsellor, or a general question); the language you would prefer to be contacted in, if you want to tell us; and a short message of between 20 and 2,000 characters. There is one tick box, which you have to tick before the form will send. There is also one field that is hidden from view and is not meant to be filled in at all: it is there to catch automated spam, and if your browser or your screen reader shows it to you, please leave it blank.

There is no date of birth, no postal address, no telephone number, no question about what you are struggling with, no list of conditions to choose from, and nothing that asks how urgent your situation is. The limit on the message box is deliberate: it is the main thing we do to keep sensitive information out of an email inbox, where it does not belong.

The warning above the message box

Immediately above the message box, in ordinary text rather than small print, the form says this:

Please do not write about your health, your symptoms, a diagnosis or your personal circumstances here. Just tell us which service you are interested in, and we will reply by email so we can arrange a private conversation.

We mean it. Nothing you send through this website is covered by counselling confidentiality: no counselling relationship exists at that point, and the enquiry mailbox is read as a business mailbox, not by a counsellor in a session. Ostwalden has no employees. Today your message is read by our sole director, Xinze Guo, who is also the person responsible for data protection here. If anyone else is ever given access, we will say so on this page. The safe place for anything personal is the conversation that follows, not the form.

If you tell us anyway

People do, and we would rather plan for that than pretend otherwise. The law treats information about your mental or physical health as special category information, and Article 9(1) of the UK GDPR prohibits us from using it at all unless a specific condition applies. A message sent to a counselling service can say something about a person's health even when it is carefully worded, so we are not going to claim that we never receive health information. We deal with it like this.

  • Our lawful basis under Article 6 is legitimate interests, Article 6(1)(f). The interest is a plain one: answering somebody who has asked about our service, and being a counselling service that people can actually contact. We have carried out the balancing assessment behind that. You can ask us for a copy.
  • Our condition under Article 9 is your explicit consent, Article 9(2)(a). The form will not send until you tick a box. It is not pre-ticked, it is the only box of its kind on the form, and it does nothing else — it does not sign you up to anything and it is not bundled with accepting our terms. It says that you understand your message may contain information about your health or your circumstances, that Ostwalden may use that information to reply to you, and that if you ask us to put you in touch with a counsellor we may pass it to that counsellor.
  • You do not have to give that consent, and you do not have to use the form. We will be straight with you: because the box is required, the form is not the right route for anyone who does not want to give this consent. The alternative is to email info@ostwalden.co.uk, where no box arises and no consent is asked for. We say so next to the box as well as here, because a choice you only find out about afterwards is not a choice.
  • You can take the consent back at any time. Email us and we will delete your message. Withdrawing consent does not make what we did beforehand unlawful, but it stops us going any further.
  • If health information reaches us another way — in an email sent straight to our mailbox, for instance, where there is no tick box — we do not use it for anything beyond identifying who you are and what you are asking. We reply, tell you plainly that you did not have to send it, and ask you to confirm in writing whether you are content for us to use what you sent. If you confirm, we rely on your explicit consent under Article 9(2)(a) from that point. If you say no, or you do not reply, we delete the message. In any event we delete or black out anything we do not need within 14 days. Where a message discloses a serious risk to someone's safety, section 10 applies instead and explains what we rely on.

We keep a note of which version of the consent wording was in force when your enquiry was sent, together with the reference number, the date and the time. That note sits with the operational record described in section 4 and is deleted with it. It does not contain your message. We also keep the version history of the consent wording itself, which names nobody and is not linked to any individual, for 2 years, so that we can always show you the exact words you were shown.

Do you have to give us any of this?

No. There is no legal or contractual requirement to give us anything, and nothing follows from refusing except the obvious: without an email address we cannot reply to you, and without a name we will not know what to call you.

And if you are unhappy with any of it

We would rather say this here, at the point you are deciding what to send us, than only after something has gone wrong. You have the right to complain to us about the way we use your information. Email info@ostwalden.co.uk. Section 13 sets out what we then have to do, and how to complain to the Information Commissioner's Office instead of us or as well as us.

4. What we collect, why, our lawful basis, and how long we keep it

What we collect Why Our lawful basis How long we keep it
Enquiry form: your name or nickname, your email address, which service your enquiry is about, your preferred language if you give it, and your message To read your enquiry and reply to it Article 6(1)(f) — our legitimate interest in answering people who ask about our service 6 months after the last message in the exchange, then deleted
Health information or personal circumstances you choose to put in your message To reply to you, and to pass to a counsellor if you ask us to Article 6(1)(f) as above, together with Article 9(2)(a) — your explicit consent, given on the form Deleted with the rest of the enquiry at 6 months, or sooner if you withdraw your consent. Where it reaches us without that consent, dealt with as described in section 3 and deleted or redacted within 14 days
A note of the consent version in force when your enquiry was sent, with its reference number, date and time So we can show what you actually agreed to Article 6(1)(c) — a legal obligation, because Article 7(1) requires us to be able to demonstrate consent Up to 30 days, with the rest of the operational record. The consent wording itself, which identifies nobody, is kept for 2 years
Operational record of an enquiry: a reference number, the date and time, a salted one-way hash of your IP address, a spam score, and the service you selected To trace an enquiry that goes missing, and to detect and block automated spam and abuse of the form Article 6(1)(f) — our legitimate interest in a contact form that works and is not overwhelmed by spam Up to 30 days, then deleted
A copy of your message written to a failure log, but only where the email carrying it could not be delivered So that nothing you wrote is lost when delivery fails, and so that we can send it on Article 6(1)(f) as above, together with Article 9(2)(a) — your explicit consent — where the message contains information about your health Deleted within 30 days of the delivery failure, and sooner once we have dealt with it
Job applications sent to our mailbox: your CV, contact details, work history, right to work information and referees To consider you for a role and to take up references Article 6(1)(b) — steps taken at your request before entering a contract 6 months after we tell you the outcome, then deleted. Ostwalden has no employees today. If we take someone on, their application becomes part of their employment file, which we keep for 6 years after they leave. Where the law obliges us to keep a particular record for longer, we keep it for that period and no longer, and we will say so here if that ever applies
Anything sensitive an applicant chooses to include in a CV or covering letter — health, ethnic origin, religion We never ask for it. Where we do use it, it is to meet our duties as an employer, for example to make an adjustment for an interview Article 9(2)(b), with paragraph 1 of Part 1 of Schedule 1 to the Data Protection Act 2018. We keep the appropriate policy document that paragraph requires Removed as soon as we no longer need it, and in any event deleted with the rest of the application
Counsellor applications: name, contact details, professional body and registration number, qualifications, insurance and supervision arrangements To check that a counsellor is who they say they are, and is registered, insured and properly supervised. We have not yet engaged any counsellors; this describes what we will do when we do Article 6(1)(b) — steps taken at the counsellor's request before entering a contract 6 months if we do not engage you. If we do, for as long as you work with us and for 6 years afterwards
Server access logs: your IP address, the date and time, the page requested, and your browser and device type To keep the site running and to investigate attacks and faults Article 6(1)(f) — our legitimate interest in the security of our own website 14 days, then deleted
Security and bot-detection information handled by Cloudflare To stop attacks, abuse and automated spam before they reach us Article 6(1)(f) — our legitimate interest in the security of our own website Held by Cloudflare for short periods under its own retention rules. We keep no copy of Cloudflare's records
The record of the cookie choice you made So that a choice you have made about cookies is remembered and honoured Strictly necessary under Schedule A1 to the Privacy and Electronic Communications Regulations, because without it we could not honour the answer you gave us Until you change your choice or clear your browser storage. Stored in your browser only. It never reaches our server and contains nothing that identifies you
A record of a safeguarding disclosure, in the rare case where we have had to make one To show what we did, when, and why Article 6(1)(d) and Article 6(1)(ea), with Article 9(2)(c) and paragraph 18 of Part 2 of Schedule 1 to the Data Protection Act 2018. See section 10 6 years from the date of the record

Where a period is stated above, we mean it as a deadline and not as an aspiration. We go through the mailbox at the start of each month and delete whatever has passed its date.

Anti-spam, and the record our server keeps of an enquiry

Two of the rows above describe things our server creates rather than things you type, so they deserve a plain explanation.

A contact form on an open website attracts a great deal of automated traffic. Four things sit in the way of it:

  • A signed, single-use token. The page gives your browser a token when the form loads. It is valid for a limited time and can be used once, so a script cannot send the form over and over.
  • A hidden field. It is positioned off the screen and no answer is expected. Automated scripts tend to fill in every field they find, so anything written there marks the submission as automated. Leave it blank.
  • A minimum time to fill the form in. A submission that arrives within a second or two of the page loading was almost certainly not typed by a person.
  • A limit on how many submissions come from the same internet connection in a short period.

Out of those checks our server produces a spam score, and it keeps a short operational record of the submission: a reference number, the date and time, a salted one-way hash of your IP address (a scrambled value we cannot turn back into your IP address), that spam score, and which service you chose. That record lets us trace an enquiry that seems to have gone missing and lets us see a spam attack for what it is. It does not contain your name, your email address or your message. We keep it for up to 30 days and then delete it.

These checks can stop a genuine message. If a message of yours does not seem to have arrived, please email info@ostwalden.co.uk directly. Ordinary email is not subject to any of this.

5. Information that reaches us from someone other than you

Sometimes we end up holding information about a person who has not written to us themselves. Article 14 of the UK GDPR requires us to say so, and to say where it came from.

  • Someone enquiring on another person's behalf. A partner, a relative or a friend sometimes writes to ask about counselling for somebody else. We then hold whatever they have told us about that person, usually a name and something about their situation. We ask people not to do this, because it is better for the person concerned to write themselves. Where we do end up holding information about someone this way, we will tell them within one month, or when we first contact them if that comes sooner, unless telling them would itself put them at risk.
  • Counsellors who apply to work with us. We have not yet engaged any counsellors. When one applies, most of what we hold will come from the counsellor. We will also check their entry on the public register kept by their professional body — the BACP Register of Counsellors and Psychotherapists, or the UKCP register. Those registers are published by those bodies and anyone can search them.
  • Referees. Where a job applicant or a counsellor gives us a referee's name, we hold that referee's contact details, which came from the applicant, and whatever the referee then tells us.

6. Who else sees your information

This is the list as it stands today. If we add anyone to it, we will update this page.

  • Vultr (The Constant Company, LLC), whose server in Singapore runs this website and receives what you type into the form. Section 7 explains what that means.
  • Cloudflare, Inc., which sits in front of the website as a content delivery network, DNS provider and security filter. Every request to the site passes through it.
  • Namecheap Private Email, our mailbox provider, where enquiry notifications arrive and are read.
  • [to be confirmed], which will send automated confirmation emails once we switch that on. It is not in use yet, we have not set a date, and we will update this notice before we switch it on.
  • A counsellor, if and when you ask us to put you in touch with one. We have not yet engaged any counsellors, so nothing has been passed to one. When we do, we will pass on what you have told us to that counsellor and to nobody else, and only where you have asked us to. Counsellors are independent practitioners registered with BACP or UKCP. Once your information reaches a counsellor, that counsellor decides how it is used and answers for it in their own right, under their own professional obligations and their own privacy notice. They are a controller, not our processor.
  • Our professional advisers — our solicitors, accountants and insurers — where we genuinely need their advice, and only as much of it as they need.
  • Anyone we are required by law to disclose to, including under a court order, and the emergency and safeguarding services in the circumstances described in section 10.

Our hosting provider, Cloudflare and our mailbox provider are our processors. They act on our written instructions under contracts that meet Article 28 of the UK GDPR, and they may not use your information for their own purposes. The email sending provider named above is not engaged yet. We will not switch it on until an Article 28 contract and a transfer safeguard are in place, and we will name it here at the same time.

We do not sell your information. We do not share it with anybody for marketing. We do not use it to build a profile of you.

7. Sending information outside the United Kingdom

Some of your information leaves the United Kingdom. We would rather tell you exactly where it goes than use the usual sentence about countries that may not offer the same level of protection, which tells you nothing.

Singapore, where this website is hosted

The server that runs ostwalden.co.uk and receives the enquiry form sits in a data centre in Singapore, operated by Vultr (The Constant Company, LLC). Singapore is not covered by UK adequacy regulations. There is no finding that Singapore protects personal information to a standard equivalent to the United Kingdom's, and we are not going to imply that there is.

We therefore rely on a safeguard under Article 46 of the UK GDPR. Our contract with the hosting provider incorporates the UK International Data Transfer Addendum to the EU standard contractual clauses, which that provider offers as standard. Where a provider does not offer the EU clauses, we use the standalone International Data Transfer Agreement issued by the ICO instead. Article 46, as it now stands, also requires us to be satisfied that the data protection test is met — that the protection your information would receive in Singapore is not materially lower than the protection it has here. We have carried out that assessment, we have recorded it, and we keep it on file.

The form is built so that as little as possible comes to rest in Singapore. The small program that receives your message passes it straight on by email and does not keep the content of a delivered enquiry on that server. There is one exception, and it matters. If the email carrying your message cannot be delivered, the message is written to a failure log on the server so that what you wrote is not simply lost. We check those failures, send the message on, and delete the log entry within 30 days. Nothing else you write is stored there.

The United States, for content delivery and email

Cloudflare, Inc. is a United States company. Everything you send through this site passes through its network, which decrypts and re-encrypts it on the way, so Cloudflare is technically able to see the contents of your message in transit as well as your IP address. That is how a content delivery network and a web application firewall work, and it is a reason to keep the form short.

Enquiry notifications arrive in our mailbox with Namecheap Private Email, run by a United States company. If we switch on automated confirmation emails they will be sent through [to be confirmed], also based in the United States. That is not in use today.

The United States is covered by UK adequacy regulations only in part. The cover extends to organisations holding an active certification under the UK Extension to the EU-US Data Privacy Framework, and only for the categories of information they have registered to receive. Where a provider we use holds that certification, the transfer is covered by those regulations. Where it does not, we use the UK Addendum described above and complete the same data protection test. We check each provider's entry on the Data Privacy Framework list rather than assuming it.

Asking us for a copy

You can ask for a copy of the safeguards we use for any of these transfers. Email info@ostwalden.co.uk and we will send it to you. Where a document contains commercial terms that have nothing to do with you, we will send it with those parts removed.

8. Cookies and what is stored in your browser

This site uses very little. There are no analytics cookies, no advertising cookies and no tracking of any kind at present. What there is:

  • Your cookie choice. A single entry in your browser's own storage, called ostwalden_cookie_choice, recording the choice you made. It stays on your device until you change your choice or clear your browser storage, it never reaches our server, and it contains nothing that identifies you.
  • Cloudflare's own security cookies, named __cf_bm, cf_clearance and _cfuvid. Cloudflare sets these to tell genuine visitors from automated traffic and to protect the site from attack. cf_clearance is set only where Cloudflare asks your browser to complete a security check, which can happen at any time and which you may have to pass before a page will load or the form will send. We do not use Cloudflare Turnstile on the form today. If we switch it on, we will say so here and in our Cookie Policy before we do, and email will always remain a route to us that involves no check of any kind.
  • A short-lived token for the enquiry form. A signed cookie called ostwalden_form_token, used once and valid for less than an hour, so that automated scripts cannot flood the form with spam.

Our Cookie Policy lists each one by name, provider, purpose and duration, and says which exception under the Privacy and Electronic Communications Regulations we rely on for it. If we ever decide we want analytics, we will ask you first, and refusing will be exactly as easy as agreeing.

9. How we look after your information

  • Everything travels to and from this website over an encrypted connection.
  • The program that receives the enquiry form relays your message by email and does not keep the content of a delivered enquiry on the server. If delivery fails, the message is written to a failure log so that it is not lost to you, and that entry is dealt with and deleted within 30 days.
  • Enquiries go to a single company mailbox on our own domain, protected by two-factor authentication. Ostwalden has no employees, and today only our sole director has access to it. If we take anyone on, access will be given by name and only where the person needs it, and we will update this notice. We do not forward enquiries to personal email accounts or to consumer messaging apps.
  • Server access logs, which include your IP address, are kept for 14 days so that we can investigate attacks and faults, and are then deleted.
  • The operational record of an enquiry described in section 4 is kept for up to 30 days and then deleted.
  • We do not sell your information, share it for marketing, or use it to profile you.

No website and no email system can be made completely secure, and we are not going to tell you otherwise. If personal information is lost, disclosed or accessed when it should not have been, we will report it to the ICO within 72 hours of becoming aware of it where the law requires us to, and we will tell you directly where the breach is likely to put your rights and freedoms at high risk.

10. If we think someone is at serious risk

Ostwalden is not an emergency or a crisis service, and we do not read the enquiry mailbox around the clock. If you are in danger now, or you are thinking about harming yourself, please use one of these instead of waiting for us: call 999; call 111 and choose the mental health option; call Samaritans free on 116 123, at any hour of the day or night; or, if you would rather text than talk, text SHOUT to 85258, free and at any hour.

Very occasionally a message tells us that someone's life may be in danger, or that an adult at risk or a child may be being harmed. If we judge that to be the case, we may pass on what we know to the emergency services, to a GP, or to the safeguarding team at the relevant local authority. We do not do this lightly, and we do not do it often.

When we do, our lawful basis is Article 6(1)(d) of the UK GDPR, protecting someone's vital interests, and, where it applies, the recognised legitimate interest of safeguarding a vulnerable individual under Article 6(1)(ea) and Annex 1 to the UK GDPR. For health information we rely on Article 9(2)(c), which covers vital interests where the person is not capable of giving consent, and on the safeguarding condition in paragraph 18 of Part 2 of Schedule 1 to the Data Protection Act 2018. That condition requires us to keep an appropriate policy document, and we keep one.

Wherever it is safe to do so, we will tell you that we have done this and what we passed on.

11. Automated decisions and profiling

We do not make any significant decision about you by automated means within the meaning of Articles 22A to 22D of the UK GDPR. Nothing on this site ranks you, sorts you by how urgent your situation appears, or decides what help you are offered. Every enquiry that reaches us is read and answered by a person.

Two automated checks do sit in front of the form, and we would rather name them than leave them out. Our own server gives each submission a spam score. That score is based on how quickly the form was filled in, whether the hidden anti-spam field was completed, whether the form's signed single-use token was valid and still in date, and how many submissions have recently come from the same internet connection. Separately, Cloudflare's security filter can challenge your browser, or block a request outright, before it reaches us at all. Either can stop a genuine message getting through. Neither reads what you have written about yourself, and neither decides anything about the help you are offered.

If a message of yours does not seem to have arrived, email info@ostwalden.co.uk directly. Ordinary email is not subject to these checks, and we would always rather hear from you twice than not at all.

If we ever build something that does make a decision about you — the obvious candidate is software that suggests which counsellors might suit you — we will assess it under Articles 22A to 22D before we build it rather than afterwards, and we will say so here.

12. Your rights

These rights are free to use. There is no form to fill in and no particular form of words: email info@ostwalden.co.uk and tell us what you want. If we are not sure who you are, we will ask you to confirm it, because we are not going to hand your information to somebody else.

  • Get a copy of what we hold about you, and be told what we do with it. Article 15.
  • Have something corrected if it is wrong or incomplete. Article 16.
  • Ask us to delete it. Article 17. This right is not absolute — we can refuse where we still need the information for a legal claim or where the law requires us to keep it — but for a website enquiry it will almost always be available, and if you withdraw the consent described in section 3 we will delete the message.
  • Ask us to pause, rather than delete. Article 18, where you are disputing our use of something and want it put on hold while that is sorted out.
  • Object to what we are doing. Article 21. Because we rely on legitimate interests for enquiries, for the operational record and for our security logs, you can object at any time, and we must stop unless we can show compelling legitimate grounds that override your interests. If we ever send you marketing, you can object to that and we must stop, with no argument and no balancing exercise.
  • Take your information elsewhere. Article 20. This applies to information we hold because you gave your consent — in practice, the health information you chose to include in your message. You can ask us for it in a common, machine-readable format, or ask us to send it directly to someone else where that is technically possible. Most of what we hold about an enquirer rests on legitimate interests rather than consent, so this right will often not apply.
  • Withdraw a consent you gave. Article 7(3), at any time and as easily as you gave it.
  • Rights about automated decisions. Articles 22A to 22D. These do not arise here, because we make no significant decision about you by automated means. Section 11 explains the two spam checks that do run, and what to do if one of them has stopped your message.
  • Complain. To us, and to the ICO. See section 13.

How long we take

We answer within one month. The law is now precise about when that month starts: it runs from the latest of the day we receive your request, the day we receive any confirmation of identity we have asked you for, and the day any fee we are entitled to charge is paid. If we have to ask you which information you want, the clock pauses while we wait for your answer. If a request is genuinely complex or you have made several, we may extend by up to two further months, and we will tell you within the first month if we are going to and why.

13. How to complain

Complain to us

If you are unhappy with anything we have done with your information, tell us. Email info@ostwalden.co.uk with "Data protection complaint" in the subject line, or write to us at our registered office. You can also raise it in any other message you send us, including a reply to an email from us. However your complaint reaches us, we will accept it and treat it as a complaint, and you do not have to use any particular wording or quote any particular section of the law. We would steer you away from the enquiry form for this one thing: it is built for service enquiries, it asks you to tick a box about health information, and it limits how much you can write.

Section 164A of the Data Protection Act 2018 gives you the right to complain to us and sets out what we then have to do. We will acknowledge your complaint within 30 days of receiving it. We will take appropriate steps to deal with it without undue delay, and we will tell you the outcome.

We should be straight with you about who will look at it. Ostwalden has no employees, so it will be looked at by our sole director. We cannot offer you an independent review inside this company, and we are not going to pretend we can. That is one reason the route to the ICO below matters, and you can use it at any point.

Complain to the ICO

You can also complain to the Information Commissioner's Office, under section 165 of the Data Protection Act 2018. You do not have to complain to us first, although it is usually quicker if you do.

  • Online: ico.org.uk/make-a-complaint
  • Helpline: 0303 123 1113
  • By post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF

Complaining to the ICO does not affect any other right you have, including your right to go to court.

If your complaint is about a counsellor

Counsellors are independent practitioners. Once your information has reached a counsellor, that counsellor decides how it is used and answers for it in their own right. A complaint about a counsellor's handling of your information goes to that counsellor, and you can also raise it with their professional body and with the ICO. If you are not sure who to write to, ask us and we will tell you.

14. People under 18

Our service is for adults aged 18 and over. We do not knowingly collect information about anyone under 18, and we do not take on clients under 18. If we realise that an enquiry has come from someone under 18, we delete it and reply explaining where to find help.

If you are under 18 and you want to talk to someone: your GP can refer you, your school or college may have a counselling service, and Childline is free on 0800 1111, day or night.

15. What will change when booking goes live

We intend to add booking and payment later, with sessions bought in advance in blocks. That is a different kind of processing altogether, and a far more sensitive one. It will involve an account, payment records, appointment records and, in the counsellor's hands, counselling notes.

None of that exists today, and nothing in this notice describes it. Before any of it starts we will:

  1. carry out a data protection impact assessment;
  2. work out afresh which Article 9 condition applies to counselling records, which is a different question from the one answered in section 3;
  3. decide again whether a Data Protection Officer is required;
  4. set out clearly which records belong to Ostwalden and which belong to the counsellor, and who answers for what;
  5. decide where counselling records will be held, and assess any software that suggests a counsellor under Articles 22A to 22D.

Counselling records will be covered by their own separate notice, not by this one. We will publish it before bookings open, and we will tell you before any change takes effect.

16. Changes to this notice, the language it is written in, and the law that applies

This is version 1.0, published on 22 September 2026. It is the first version, so there is nothing yet to compare it with. When we change it we will update the date, raise the version number and add a short note saying what changed. If a change matters to you, we will tell you before it takes effect rather than expecting you to notice.

This notice is written in English. If you would find it easier to read in Chinese, email info@ostwalden.co.uk and we will send you a translation. Where the two versions differ, the English version is the one that governs.

This notice, and any dispute about it, is governed by the law of England and Wales. Nothing here takes away your right to bring a claim in the courts of the part of the United Kingdom where you live, and nothing here requires you to use arbitration instead of going to court.